Google: sys-kernel/cchost-kernel-6_12, sys-kernel/csql-kernel-6_12, sys-kernel/lakitu-kernel-6_12, sys-kernel/lakitu-nc-kernel-6_12: security update to 19506.299.82

medium Tenable Cloud Security Plugin ID 469626

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In the Linux kernel, the following vulnerability has been resolved: iommufd: Set upper bounds on cache
invalidation entry_num and entry_len iommufd_hwpt_invalidate() takes a user-controlled entry_num and
entry_len, each bounded only by U32_MAX. An entry_len beyond the kernel's struct size makes the copy
helper verify the extra bytes are zero, scanning that excess in one uninterruptible pass; a multi-gigabyte
value over zeroed user memory trips the soft-lockup watchdog. A large entry_num is the other half, driving
the backend invalidation loop with no reschedule. The VT-d nested handler, for one, copies each entry and
flushes caches per iteration, pinning the CPU on a non-preemptible kernel. Cap both in the ioctl.
entry_len is held under PAGE_SIZE, above any request struct, and entry_num under 1 << 19, the order of a
hardware invalidation queue and well beyond any real batch, bounding the per-call loop length.
(CVE-2026-64289)

Solution

Update the sys-kernel/cchost-kernel-6_12 library and its related packages to version 19506.299.82 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-129.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 469626

Version: Revision 1.6

Type: Local

Published: 10/3/2026

Updated: 10/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.72

Vendor

Vendor Severity: MEDIUM

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-64289

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/23/2026

Reference Information

CVE: CVE-2026-64289